4
CVSSv2

CVE-2018-11802

Published: 01/04/2020 Updated: 03/04/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions before 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache solr